1a9148abdSDoug Rabson /*-
2a9148abdSDoug Rabson * Copyright (c) 2008 Isilon Inc http://www.isilon.com/
3a9148abdSDoug Rabson * Authors: Doug Rabson <dfr@rabson.org>
4a9148abdSDoug Rabson * Developed with Red Inc: Alfred Perlstein <alfred@freebsd.org>
5a9148abdSDoug Rabson *
6a9148abdSDoug Rabson * Redistribution and use in source and binary forms, with or without
7a9148abdSDoug Rabson * modification, are permitted provided that the following conditions
8a9148abdSDoug Rabson * are met:
9a9148abdSDoug Rabson * 1. Redistributions of source code must retain the above copyright
10a9148abdSDoug Rabson * notice, this list of conditions and the following disclaimer.
11a9148abdSDoug Rabson * 2. Redistributions in binary form must reproduce the above copyright
12a9148abdSDoug Rabson * notice, this list of conditions and the following disclaimer in the
13a9148abdSDoug Rabson * documentation and/or other materials provided with the distribution.
14a9148abdSDoug Rabson *
15a9148abdSDoug Rabson * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
16a9148abdSDoug Rabson * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
17a9148abdSDoug Rabson * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
18a9148abdSDoug Rabson * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
19a9148abdSDoug Rabson * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
20a9148abdSDoug Rabson * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
21a9148abdSDoug Rabson * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
22a9148abdSDoug Rabson * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
23a9148abdSDoug Rabson * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
24a9148abdSDoug Rabson * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
25a9148abdSDoug Rabson * SUCH DAMAGE.
26a9148abdSDoug Rabson */
27a9148abdSDoug Rabson
28a9148abdSDoug Rabson #ifdef __FreeBSD__
29a9148abdSDoug Rabson #include <sys/cdefs.h>
30a9148abdSDoug Rabson #else
31a9148abdSDoug Rabson #define __unused
32a9148abdSDoug Rabson #endif
33a9148abdSDoug Rabson
34a9148abdSDoug Rabson #include <ctype.h>
35a9148abdSDoug Rabson #include <err.h>
36a9148abdSDoug Rabson #include <netdb.h>
37a9148abdSDoug Rabson #include <stdio.h>
38a9148abdSDoug Rabson #include <stdlib.h>
39a9148abdSDoug Rabson #include <string.h>
40a9148abdSDoug Rabson #include <unistd.h>
41a9148abdSDoug Rabson
42a9148abdSDoug Rabson #include <rpc/rpc.h>
43a9148abdSDoug Rabson #include <rpc/rpcsec_gss.h>
44a9148abdSDoug Rabson
45a9148abdSDoug Rabson static rpc_gss_principal_t server_acl = NULL;
46a9148abdSDoug Rabson
47a9148abdSDoug Rabson static void
usage(void)48a9148abdSDoug Rabson usage(void)
49a9148abdSDoug Rabson {
50a9148abdSDoug Rabson printf("rpctest client | server\n");
51a9148abdSDoug Rabson exit(1);
52a9148abdSDoug Rabson }
53a9148abdSDoug Rabson
54a9148abdSDoug Rabson static void
print_principal(rpc_gss_principal_t principal)55a9148abdSDoug Rabson print_principal(rpc_gss_principal_t principal)
56a9148abdSDoug Rabson {
57a9148abdSDoug Rabson int i, len, n;
58a9148abdSDoug Rabson uint8_t *p;
59a9148abdSDoug Rabson
60a9148abdSDoug Rabson len = principal->len;
61a9148abdSDoug Rabson p = (uint8_t *) principal->name;
62a9148abdSDoug Rabson while (len > 0) {
63a9148abdSDoug Rabson n = len;
64a9148abdSDoug Rabson if (n > 16)
65a9148abdSDoug Rabson n = 16;
66a9148abdSDoug Rabson for (i = 0; i < n; i++)
67a9148abdSDoug Rabson printf("%02x ", p[i]);
68a9148abdSDoug Rabson for (; i < 16; i++)
69a9148abdSDoug Rabson printf(" ");
70a9148abdSDoug Rabson printf("|");
71a9148abdSDoug Rabson for (i = 0; i < n; i++)
72a9148abdSDoug Rabson printf("%c", isprint(p[i]) ? p[i] : '.');
73a9148abdSDoug Rabson printf("|\n");
74a9148abdSDoug Rabson len -= n;
75a9148abdSDoug Rabson p += n;
76a9148abdSDoug Rabson }
77a9148abdSDoug Rabson }
78a9148abdSDoug Rabson
79a9148abdSDoug Rabson static void
test_client(int argc,const char ** argv)80a9148abdSDoug Rabson test_client(int argc, const char **argv)
81a9148abdSDoug Rabson {
82a9148abdSDoug Rabson rpcproc_t prog = 123456;
83a9148abdSDoug Rabson rpcvers_t vers = 1;
84a9148abdSDoug Rabson const char *netid = "tcp";
85a9148abdSDoug Rabson char hostname[128], service[128+5];
86a9148abdSDoug Rabson CLIENT *client;
87a9148abdSDoug Rabson AUTH *auth;
88a9148abdSDoug Rabson const char **mechs;
89a9148abdSDoug Rabson rpc_gss_options_req_t options_req;
90a9148abdSDoug Rabson rpc_gss_options_ret_t options_ret;
91a9148abdSDoug Rabson rpc_gss_service_t svc;
92a9148abdSDoug Rabson struct timeval tv;
93a9148abdSDoug Rabson enum clnt_stat stat;
94a9148abdSDoug Rabson
95a9148abdSDoug Rabson if (argc == 2)
96a9148abdSDoug Rabson strlcpy(hostname, argv[1], sizeof(hostname));
97a9148abdSDoug Rabson else
98a9148abdSDoug Rabson gethostname(hostname, sizeof(hostname));
99a9148abdSDoug Rabson
100a9148abdSDoug Rabson client = clnt_create(hostname, prog, vers, netid);
101a9148abdSDoug Rabson if (!client) {
102a9148abdSDoug Rabson printf("rpc_createerr.cf_stat = %d\n",
103a9148abdSDoug Rabson rpc_createerr.cf_stat);
104a9148abdSDoug Rabson printf("rpc_createerr.cf_error.re_errno = %d\n",
105a9148abdSDoug Rabson rpc_createerr.cf_error.re_errno);
106a9148abdSDoug Rabson return;
107a9148abdSDoug Rabson }
108a9148abdSDoug Rabson
109a9148abdSDoug Rabson strcpy(service, "host");
110a9148abdSDoug Rabson strcat(service, "@");
111a9148abdSDoug Rabson strcat(service, hostname);
112a9148abdSDoug Rabson
113a9148abdSDoug Rabson mechs = rpc_gss_get_mechanisms();
114a9148abdSDoug Rabson auth = NULL;
115a9148abdSDoug Rabson while (*mechs) {
116a9148abdSDoug Rabson options_req.req_flags = GSS_C_MUTUAL_FLAG;
117a9148abdSDoug Rabson options_req.time_req = 600;
118a9148abdSDoug Rabson options_req.my_cred = GSS_C_NO_CREDENTIAL;
119a9148abdSDoug Rabson options_req.input_channel_bindings = NULL;
120a9148abdSDoug Rabson auth = rpc_gss_seccreate(client, service,
121a9148abdSDoug Rabson *mechs,
122a9148abdSDoug Rabson rpc_gss_svc_none,
123a9148abdSDoug Rabson NULL,
124a9148abdSDoug Rabson &options_req,
125a9148abdSDoug Rabson &options_ret);
126a9148abdSDoug Rabson if (auth)
127a9148abdSDoug Rabson break;
128a9148abdSDoug Rabson mechs++;
129a9148abdSDoug Rabson }
130a9148abdSDoug Rabson if (!auth) {
131a9148abdSDoug Rabson clnt_pcreateerror("rpc_gss_seccreate");
132a9148abdSDoug Rabson printf("Can't authenticate with server %s.\n",
133a9148abdSDoug Rabson hostname);
134a9148abdSDoug Rabson exit(1);
135a9148abdSDoug Rabson }
136a9148abdSDoug Rabson client->cl_auth = auth;
137a9148abdSDoug Rabson
138a9148abdSDoug Rabson for (svc = rpc_gss_svc_none; svc <= rpc_gss_svc_privacy; svc++) {
139a9148abdSDoug Rabson const char *svc_names[] = {
140a9148abdSDoug Rabson "rpc_gss_svc_default",
141a9148abdSDoug Rabson "rpc_gss_svc_none",
142a9148abdSDoug Rabson "rpc_gss_svc_integrity",
143a9148abdSDoug Rabson "rpc_gss_svc_privacy"
144a9148abdSDoug Rabson };
145a9148abdSDoug Rabson int num;
146a9148abdSDoug Rabson
147a9148abdSDoug Rabson rpc_gss_set_defaults(auth, svc, NULL);
148a9148abdSDoug Rabson tv.tv_sec = 5;
149a9148abdSDoug Rabson tv.tv_usec = 0;
150a9148abdSDoug Rabson num = 42;
151a9148abdSDoug Rabson stat = CLNT_CALL(client, 1,
152a9148abdSDoug Rabson (xdrproc_t) xdr_int, (char *) &num,
153a9148abdSDoug Rabson (xdrproc_t) xdr_int, (char *) &num, tv);
154a9148abdSDoug Rabson if (stat == RPC_SUCCESS) {
155a9148abdSDoug Rabson printf("succeeded with %s\n", svc_names[svc]);
156a9148abdSDoug Rabson if (num != 142)
157a9148abdSDoug Rabson printf("unexpected reply %d\n", num);
158a9148abdSDoug Rabson } else {
159a9148abdSDoug Rabson clnt_perror(client, "call failed");
160a9148abdSDoug Rabson }
161a9148abdSDoug Rabson }
162a9148abdSDoug Rabson AUTH_DESTROY(auth);
163a9148abdSDoug Rabson CLNT_DESTROY(client);
164a9148abdSDoug Rabson }
165a9148abdSDoug Rabson
166a9148abdSDoug Rabson static void
server_program_1(struct svc_req * rqstp,register SVCXPRT * transp)167a9148abdSDoug Rabson server_program_1(struct svc_req *rqstp, register SVCXPRT *transp)
168a9148abdSDoug Rabson {
169a9148abdSDoug Rabson rpc_gss_rawcred_t *rcred;
170a9148abdSDoug Rabson rpc_gss_ucred_t *ucred;
171a9148abdSDoug Rabson int i, num;
172a9148abdSDoug Rabson
173a9148abdSDoug Rabson if (rqstp->rq_cred.oa_flavor != RPCSEC_GSS) {
174a9148abdSDoug Rabson svcerr_weakauth(transp);
175a9148abdSDoug Rabson return;
176a9148abdSDoug Rabson }
177a9148abdSDoug Rabson
178a9148abdSDoug Rabson if (!rpc_gss_getcred(rqstp, &rcred, &ucred, NULL)) {
179a9148abdSDoug Rabson svcerr_systemerr(transp);
180a9148abdSDoug Rabson return;
181a9148abdSDoug Rabson }
182a9148abdSDoug Rabson
183a9148abdSDoug Rabson printf("svc=%d, mech=%s, uid=%d, gid=%d, gids={",
184a9148abdSDoug Rabson rcred->service, rcred->mechanism, ucred->uid, ucred->gid);
185a9148abdSDoug Rabson for (i = 0; i < ucred->gidlen; i++) {
186a9148abdSDoug Rabson if (i > 0) printf(",");
187a9148abdSDoug Rabson printf("%d", ucred->gidlist[i]);
188a9148abdSDoug Rabson }
189a9148abdSDoug Rabson printf("}\n");
190a9148abdSDoug Rabson
191a9148abdSDoug Rabson switch (rqstp->rq_proc) {
192a9148abdSDoug Rabson case 0:
193a9148abdSDoug Rabson if (!svc_getargs(transp, (xdrproc_t) xdr_void, 0)) {
194a9148abdSDoug Rabson svcerr_decode(transp);
195a9148abdSDoug Rabson goto out;
196a9148abdSDoug Rabson }
197a9148abdSDoug Rabson if (!svc_sendreply(transp, (xdrproc_t) xdr_void, 0)) {
198a9148abdSDoug Rabson svcerr_systemerr(transp);
199a9148abdSDoug Rabson }
200a9148abdSDoug Rabson goto out;
201a9148abdSDoug Rabson
202a9148abdSDoug Rabson case 1:
203a9148abdSDoug Rabson if (!svc_getargs(transp, (xdrproc_t) xdr_int,
204a9148abdSDoug Rabson (char *) &num)) {
205a9148abdSDoug Rabson svcerr_decode(transp);
206a9148abdSDoug Rabson goto out;
207a9148abdSDoug Rabson }
208a9148abdSDoug Rabson num += 100;
209a9148abdSDoug Rabson if (!svc_sendreply(transp, (xdrproc_t) xdr_int,
210a9148abdSDoug Rabson (char *) &num)) {
211a9148abdSDoug Rabson svcerr_systemerr(transp);
212a9148abdSDoug Rabson }
213a9148abdSDoug Rabson goto out;
214a9148abdSDoug Rabson
215a9148abdSDoug Rabson default:
216a9148abdSDoug Rabson svcerr_noproc(transp);
217a9148abdSDoug Rabson goto out;
218a9148abdSDoug Rabson }
219a9148abdSDoug Rabson
220a9148abdSDoug Rabson out:
221a9148abdSDoug Rabson return;
222a9148abdSDoug Rabson }
223a9148abdSDoug Rabson
224a9148abdSDoug Rabson #if 0
225a9148abdSDoug Rabson static void
226a9148abdSDoug Rabson report_error(gss_OID mech, OM_uint32 maj, OM_uint32 min)
227a9148abdSDoug Rabson {
228a9148abdSDoug Rabson OM_uint32 maj_stat, min_stat;
229a9148abdSDoug Rabson OM_uint32 message_context;
230a9148abdSDoug Rabson gss_buffer_desc buf;
231a9148abdSDoug Rabson
232a9148abdSDoug Rabson printf("major_stat=%d, minor_stat=%d\n", maj, min);
233a9148abdSDoug Rabson
234a9148abdSDoug Rabson message_context = 0;
235a9148abdSDoug Rabson do {
236a9148abdSDoug Rabson maj_stat = gss_display_status(&min_stat, maj,
237a9148abdSDoug Rabson GSS_C_GSS_CODE, GSS_C_NO_OID, &message_context, &buf);
238a9148abdSDoug Rabson printf("%.*s\n", (int)buf.length, (char *) buf.value);
239a9148abdSDoug Rabson gss_release_buffer(&min_stat, &buf);
240a9148abdSDoug Rabson } while (message_context);
241a9148abdSDoug Rabson if (mech) {
242a9148abdSDoug Rabson message_context = 0;
243a9148abdSDoug Rabson do {
244a9148abdSDoug Rabson maj_stat = gss_display_status(&min_stat, min,
245a9148abdSDoug Rabson GSS_C_MECH_CODE, mech, &message_context, &buf);
246a9148abdSDoug Rabson printf("%.*s\n", (int)buf.length, (char *) buf.value);
247a9148abdSDoug Rabson gss_release_buffer(&min_stat, &buf);
248a9148abdSDoug Rabson } while (message_context);
249a9148abdSDoug Rabson }
250a9148abdSDoug Rabson exit(1);
251a9148abdSDoug Rabson }
252a9148abdSDoug Rabson #endif
253a9148abdSDoug Rabson
254a9148abdSDoug Rabson static bool_t
server_new_context(__unused struct svc_req * req,__unused gss_cred_id_t deleg,__unused gss_ctx_id_t gss_context,rpc_gss_lock_t * lock,__unused void ** cookie)255a9148abdSDoug Rabson server_new_context(__unused struct svc_req *req,
256a9148abdSDoug Rabson __unused gss_cred_id_t deleg,
257a9148abdSDoug Rabson __unused gss_ctx_id_t gss_context,
258a9148abdSDoug Rabson rpc_gss_lock_t *lock,
259a9148abdSDoug Rabson __unused void **cookie)
260a9148abdSDoug Rabson {
261a9148abdSDoug Rabson rpc_gss_rawcred_t *rcred = lock->raw_cred;
262a9148abdSDoug Rabson
263a9148abdSDoug Rabson printf("new security context version=%d, mech=%s, qop=%s:\n",
264a9148abdSDoug Rabson rcred->version, rcred->mechanism, rcred->qop);
265a9148abdSDoug Rabson print_principal(rcred->client_principal);
266a9148abdSDoug Rabson
267a9148abdSDoug Rabson if (!server_acl)
268a9148abdSDoug Rabson return (TRUE);
269a9148abdSDoug Rabson
270a9148abdSDoug Rabson if (rcred->client_principal->len != server_acl->len
271a9148abdSDoug Rabson || memcmp(rcred->client_principal->name, server_acl->name,
272a9148abdSDoug Rabson server_acl->len)) {
273a9148abdSDoug Rabson return (FALSE);
274a9148abdSDoug Rabson }
275a9148abdSDoug Rabson
276a9148abdSDoug Rabson return (TRUE);
277a9148abdSDoug Rabson }
278a9148abdSDoug Rabson
279a9148abdSDoug Rabson static void
test_server(__unused int argc,__unused const char ** argv)280a9148abdSDoug Rabson test_server(__unused int argc, __unused const char **argv)
281a9148abdSDoug Rabson {
282a9148abdSDoug Rabson char hostname[128];
283a9148abdSDoug Rabson char principal[128 + 5];
284a9148abdSDoug Rabson const char **mechs;
285a9148abdSDoug Rabson static rpc_gss_callback_t cb;
286a9148abdSDoug Rabson
287a9148abdSDoug Rabson if (argc == 3) {
288a9148abdSDoug Rabson if (!rpc_gss_get_principal_name(&server_acl, argv[1],
289a9148abdSDoug Rabson argv[2], NULL, NULL)) {
290a9148abdSDoug Rabson printf("Can't create %s ACL entry for %s\n",
291a9148abdSDoug Rabson argv[1], argv[2]);
292a9148abdSDoug Rabson return;
293a9148abdSDoug Rabson }
294a9148abdSDoug Rabson }
295a9148abdSDoug Rabson
296a9148abdSDoug Rabson gethostname(hostname, sizeof(hostname));;
297a9148abdSDoug Rabson snprintf(principal, sizeof(principal), "host@%s", hostname);
298a9148abdSDoug Rabson
299a9148abdSDoug Rabson mechs = rpc_gss_get_mechanisms();
300a9148abdSDoug Rabson while (*mechs) {
301a9148abdSDoug Rabson if (!rpc_gss_set_svc_name(principal, *mechs, GSS_C_INDEFINITE,
302a9148abdSDoug Rabson 123456, 1)) {
303a9148abdSDoug Rabson rpc_gss_error_t e;
304a9148abdSDoug Rabson
305a9148abdSDoug Rabson rpc_gss_get_error(&e);
306a9148abdSDoug Rabson printf("setting name for %s for %s failed: %d, %d\n",
307a9148abdSDoug Rabson principal, *mechs,
308a9148abdSDoug Rabson e.rpc_gss_error, e.system_error);
309a9148abdSDoug Rabson
310a9148abdSDoug Rabson #if 0
311a9148abdSDoug Rabson gss_OID mech_oid;
312a9148abdSDoug Rabson gss_OID_set_desc oid_set;
313a9148abdSDoug Rabson gss_name_t name;
314a9148abdSDoug Rabson OM_uint32 maj_stat, min_stat;
315a9148abdSDoug Rabson gss_buffer_desc namebuf;
316a9148abdSDoug Rabson gss_cred_id_t cred;
317a9148abdSDoug Rabson
318a9148abdSDoug Rabson rpc_gss_mech_to_oid(*mechs, &mech_oid);
319a9148abdSDoug Rabson oid_set.count = 1;
320a9148abdSDoug Rabson oid_set.elements = mech_oid;
321a9148abdSDoug Rabson
322a9148abdSDoug Rabson namebuf.value = principal;
323a9148abdSDoug Rabson namebuf.length = strlen(principal);
324a9148abdSDoug Rabson maj_stat = gss_import_name(&min_stat, &namebuf,
325a9148abdSDoug Rabson GSS_C_NT_HOSTBASED_SERVICE, &name);
326a9148abdSDoug Rabson if (maj_stat) {
327a9148abdSDoug Rabson printf("gss_import_name failed\n");
328a9148abdSDoug Rabson report_error(mech_oid, maj_stat, min_stat);
329a9148abdSDoug Rabson }
330a9148abdSDoug Rabson maj_stat = gss_acquire_cred(&min_stat, name,
331a9148abdSDoug Rabson 0, &oid_set, GSS_C_ACCEPT, &cred, NULL, NULL);
332a9148abdSDoug Rabson if (maj_stat) {
333a9148abdSDoug Rabson printf("gss_acquire_cred failed\n");
334a9148abdSDoug Rabson report_error(mech_oid, maj_stat, min_stat);
335a9148abdSDoug Rabson }
336a9148abdSDoug Rabson #endif
337a9148abdSDoug Rabson }
338a9148abdSDoug Rabson mechs++;
339a9148abdSDoug Rabson }
340a9148abdSDoug Rabson
341a9148abdSDoug Rabson cb.program = 123456;
342a9148abdSDoug Rabson cb.version = 1;
343a9148abdSDoug Rabson cb.callback = server_new_context;
344a9148abdSDoug Rabson rpc_gss_set_callback(&cb);
345a9148abdSDoug Rabson
346a9148abdSDoug Rabson svc_create(server_program_1, 123456, 1, 0);
347a9148abdSDoug Rabson svc_run();
348a9148abdSDoug Rabson }
349a9148abdSDoug Rabson
350a9148abdSDoug Rabson static void
test_get_principal_name(int argc,const char ** argv)351a9148abdSDoug Rabson test_get_principal_name(int argc, const char **argv)
352a9148abdSDoug Rabson {
353a9148abdSDoug Rabson const char *mechname, *name, *node, *domain;
354a9148abdSDoug Rabson rpc_gss_principal_t principal;
355a9148abdSDoug Rabson
356a9148abdSDoug Rabson if (argc < 3 || argc > 5) {
357a9148abdSDoug Rabson printf("usage: rpctest principal <mechname> <name> "
358a9148abdSDoug Rabson "[<node> [<domain>] ]\n");
359a9148abdSDoug Rabson exit(1);
360a9148abdSDoug Rabson }
361a9148abdSDoug Rabson
362a9148abdSDoug Rabson mechname = argv[1];
363a9148abdSDoug Rabson name = argv[2];
364a9148abdSDoug Rabson node = NULL;
365a9148abdSDoug Rabson domain = NULL;
366a9148abdSDoug Rabson if (argc > 3) {
367a9148abdSDoug Rabson node = argv[3];
368a9148abdSDoug Rabson if (argc > 4)
369a9148abdSDoug Rabson domain = argv[4];
370a9148abdSDoug Rabson }
371a9148abdSDoug Rabson
372a9148abdSDoug Rabson if (rpc_gss_get_principal_name(&principal, mechname, name,
373a9148abdSDoug Rabson node, domain)) {
374a9148abdSDoug Rabson printf("succeeded:\n");
375a9148abdSDoug Rabson print_principal(principal);
376a9148abdSDoug Rabson free(principal);
377a9148abdSDoug Rabson } else {
378a9148abdSDoug Rabson printf("failed\n");
379a9148abdSDoug Rabson }
380a9148abdSDoug Rabson }
381a9148abdSDoug Rabson
382a9148abdSDoug Rabson int
main(int argc,const char ** argv)383a9148abdSDoug Rabson main(int argc, const char **argv)
384a9148abdSDoug Rabson {
385a9148abdSDoug Rabson
386a9148abdSDoug Rabson if (argc < 2)
387a9148abdSDoug Rabson usage();
388a9148abdSDoug Rabson if (!strcmp(argv[1], "client"))
389a9148abdSDoug Rabson test_client(argc - 1, argv + 1);
390a9148abdSDoug Rabson else if (!strcmp(argv[1], "server"))
391a9148abdSDoug Rabson test_server(argc - 1, argv + 1);
392a9148abdSDoug Rabson else if (!strcmp(argv[1], "principal"))
393a9148abdSDoug Rabson test_get_principal_name(argc - 1, argv + 1);
394a9148abdSDoug Rabson else
395a9148abdSDoug Rabson usage();
396a9148abdSDoug Rabson
397a9148abdSDoug Rabson return (0);
398a9148abdSDoug Rabson }
399